Lucene search

K
cveRedhatCVE-2013-6441
HistoryFeb 14, 2014 - 3:55 p.m.

CVE-2013-6441

2014-02-1415:55:05
CWE-264
redhat
web.nvd.nist.gov
41
cve-2013-6441
lxc
security
privilege escalation
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

Affected configurations

Nvd
Node
linuxcontainerslxcRange0.9.0
OR
linuxcontainerslxcMatch0.1.0
OR
linuxcontainerslxcMatch0.2.0
OR
linuxcontainerslxcMatch0.2.1
OR
linuxcontainerslxcMatch0.3.0
OR
linuxcontainerslxcMatch0.4.0
OR
linuxcontainerslxcMatch0.5.0
OR
linuxcontainerslxcMatch0.5.1
OR
linuxcontainerslxcMatch0.5.2
OR
linuxcontainerslxcMatch0.6.0
OR
linuxcontainerslxcMatch0.6.1
OR
linuxcontainerslxcMatch0.6.2
OR
linuxcontainerslxcMatch0.6.3
OR
linuxcontainerslxcMatch0.6.4
OR
linuxcontainerslxcMatch0.6.5
OR
linuxcontainerslxcMatch0.7.0
OR
linuxcontainerslxcMatch0.7.1
OR
linuxcontainerslxcMatch0.7.2
OR
linuxcontainerslxcMatch0.7.3
OR
linuxcontainerslxcMatch0.7.4
OR
linuxcontainerslxcMatch0.7.4.1
OR
linuxcontainerslxcMatch0.7.4.2
OR
linuxcontainerslxcMatch0.7.5
OR
linuxcontainerslxcMatch0.8.0
VendorProductVersionCPE
linuxcontainerslxc*cpe:2.3:a:linuxcontainers:lxc:*:*:*:*:*:*:*:*
linuxcontainerslxc0.1.0cpe:2.3:a:linuxcontainers:lxc:0.1.0:*:*:*:*:*:*:*
linuxcontainerslxc0.2.0cpe:2.3:a:linuxcontainers:lxc:0.2.0:*:*:*:*:*:*:*
linuxcontainerslxc0.2.1cpe:2.3:a:linuxcontainers:lxc:0.2.1:*:*:*:*:*:*:*
linuxcontainerslxc0.3.0cpe:2.3:a:linuxcontainers:lxc:0.3.0:*:*:*:*:*:*:*
linuxcontainerslxc0.4.0cpe:2.3:a:linuxcontainers:lxc:0.4.0:*:*:*:*:*:*:*
linuxcontainerslxc0.5.0cpe:2.3:a:linuxcontainers:lxc:0.5.0:*:*:*:*:*:*:*
linuxcontainerslxc0.5.1cpe:2.3:a:linuxcontainers:lxc:0.5.1:*:*:*:*:*:*:*
linuxcontainerslxc0.5.2cpe:2.3:a:linuxcontainers:lxc:0.5.2:*:*:*:*:*:*:*
linuxcontainerslxc0.6.0cpe:2.3:a:linuxcontainers:lxc:0.6.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%